Stored Cross-Site Scripting in WP YouTube Lyte Plugin for WordPress
CVE-2026-3299
6.4MEDIUM
What is CVE-2026-3299?
The WP YouTube Lyte plugin for WordPress contains a vulnerability that allows authenticated attackers with contributor-level access or higher to exploit the 'lyte' shortcode. This is due to insufficient input sanitization and output escaping on user-supplied attributes. Attackers can inject malicious web scripts into pages, resulting in these scripts being executed whenever a user accesses the affected page, potentially compromising user data and site integrity.
Affected Version(s)
WP YouTube Lyte 0 <= 1.7.29